Ehhhhhhh...I disagree.
1. Most of my clients tend closer to seed stage than to well-funded.
2. You don’t need security expertise or money to run a good bug bounty program. You can start one immediately. There are enough high quality resources available for free on the internet (that are not content marketing) that you can learn most of the important unknown unknowns.
For example, I think this is excellent reading for any young company thinking about security: https://medium.com/starting-up-security/starting-up-security...
Sometimes, the consequences aren't high.
"Your CORS is configured to allow access from another domain, also owned by you."
"You can give yourself a redirect to any site by intercepting and modifying your own Host header."
"Your static blog on a separate domain from your actual site is accessible over unencrypted HTTP."
"If I zoom in on your web page, the text becomes blurry."
If your question was from the other end, "what do you do as the company when you get a report like this?", I say something like "We don't believe that this warrants fixing at this time. Thanks for your interest in our program, and we hope you continue reporting to us in the future!"
> Accessing private information of other users, performing actions that may negatively affect Twitter users (e.g., spam, denial of service), or sending reports from automated tools without verifying them will immediately disqualify the report
The html is almost identical - is there a checklist-templating service that you used to build this?
You can get two code implementations here: https://github.com/sqreen/CTOSecurityChecklist https://github.com/sqreen/DevOpsSecurityChecklist